fix(10.1): WR-03 walk the whole partial view model before rendering

refusedViewModel compared only the top-level type with the controller's
model. It now walks the type through pointers, slices, arrays, maps,
struct fields and the results of exported methods, and the values held
in interface-typed members, refusing the controller's model, any other
GORM model (TableName, a gorm tag, gorm.Model, gorm.DeletedAt) and
html/template's trusted content types anywhere in that structure.
This commit is contained in:
Jakub Zych
2026-09-29 09:54:35 +02:00
parent 5bbb0ada05
commit 7333f450ad
4 changed files with 277 additions and 33 deletions

View File

@@ -187,8 +187,9 @@ type HasAdminActions interface {
// renders (config_list.yaml headerPartial, fields.yaml `type: partial`). name
// is the partial name; record is the scoped record for a form partial on an
// existing record, else nil. The result must be a curated view model built
// for the template, never the GORM model itself: the framework refuses a
// value of the controller's model type.
// for the template, never a GORM model: the framework refuses a view model
// that carries the controller's model or any other GORM model, even nested
// in a field, a collection or an interface value.
type AdminPartialData interface {
PartialData(ctx context.Context, name string, record any) (any, error)
}